1. Who this policy covers
Flight MCP is an API product for individual developers and AI-agent builders. This policy applies to the website, dashboard, REST API, and MCP endpoint at flight-mcp.com.
Privacy requests can be sent to support@flight-mcp.com.
2. Data we process
- Google sign-in
- Google account identifier, name, email address, profile image, and account/session records required by Better Auth. We request basic identity scopes only.
- API access
- API-key identifier and one-way SHA-256 hash, plan entitlement, monthly cache-miss usage, request ID, response status, timing, and security events. The secret key is shown only when created.
- Flight queries
- Origin, destination, dates, traveler counts, cabin, currency, locale, point of sale, and cache preference. The API does not request passenger names, passport details, or payment-card data.
- Billing
- If paid plans are enabled, Stripe customer and subscription identifiers, plan, status, and billing-period dates. Full payment-card data is handled by Stripe and is not stored by Flight MCP.
- Technical data
- IP-derived abuse-control digests, Cloudflare security metadata, timestamps, and redacted operational logs. Burst-limit identifiers are hashed before storage in Redis.
- Optional website analytics
- If you allow analytics, Google Analytics receives page URLs, referrer, device and browser information, approximate location, and product interaction events. We do not send your email address, Google account identifier, API keys, flight-search parameters, or payment details.
3. Why we use data
- authenticate accounts and protect the dashboard;
- issue and verify API keys;
- search, normalize, cache, and return flight offers;
- enforce monthly allowances and short-term abuse controls;
- diagnose failures, prevent misuse, and answer support requests;
- manage subscriptions when paid billing is enabled.
- measure website traffic and product activation when analytics consent is granted.
4. Service providers and data transfers
Flight MCP uses Cloudflare for hosting, networking, Containers, D1, and security; Upstash for Redis; Google for account authentication and consent-based Google Analytics; Stripe for paid billing when enabled; and Decodo as the configured network proxy for provider requests. Flight-search parameters are sent to enabled flight-data sources to answer the request.
These providers may process data in countries outside your residence under their own data-protection terms. We do not sell personal information or use flight queries for targeted advertising.
5. Retention and security
Account and entitlement records are retained while the account is active and as needed for security, dispute, tax, or legal obligations. Cached flight results expire according to the requested TTL and provider policy, up to three days. Short-term burst counters expire automatically. Operational records are retained only as long as reasonably needed to operate and protect the service.
Secrets are stored in Cloudflare secret bindings. OAuth tokens are encrypted at rest by the authentication configuration. Logs redact authorization credentials, session cookies, proxy credentials, and provider payloads.
6. Your choices
You may request access, correction, export, or deletion of account data by contacting support from the Google email associated with the account. Some records may be retained where required for fraud prevention, accounting, disputes, or law.
Google Analytics is disabled until you choose “Allow analytics.” You can withdraw or change that choice at any time.
7. Changes
Material changes will be posted on this page with an updated effective date. Continued use after a change means the revised policy applies from its effective date.